Compliance Audit Export Redaction with anonym.plus

Clear identifiers from an audit export before it goes to an external reviewer.

Audit export redaction is the removal of personal identifiers from a compliance evidence file. GDPR Recital 26 excludes data that no longer points to a person. anonym.plus marks names, IDs, and contacts on your device, so the review trail stays usable while the named individuals are hidden.

When this applies

Such a sample pairs control checks with named staff and timestamps. You strip those identifiers before the evidence goes to an outside reviewer.

How anonym.plus handles it

  1. Open the export in anonym.plus on your device.
  2. The app flags named staff, IDs, and contacts.
  3. Local OCR reads a scanned evidence page.
  4. Keep the control IDs and action timestamps.
  5. Swap or black out the confirmed items.
  6. Save the clean file locally.

What you need to provide

PII entity types detected

Categoryanonym.plus entity typeExample
NamesPERSONnamed staff → [WORKER]
IdentifiersNATIONAL_IDstaff no. 33120 → [STAFF_ID]
ContactEMAIL_ADDRESSwork email → [EMAIL]
DatesDATE_TIMEaction 05/02 14:11 → [TIMESTAMP]
OrgORGANIZATIONsystem name → [SYSTEM]
LocationLOCATIONoffice site → [SITE]

Compliance achieved

Anonymize compliance audit exports offline — see plans & start free →

Limitations & cautions

A precise timestamp plus a system can still re-identify one actor even with the name gone. The app flags named items. Confirm no kept field rebuilds a link to a person before you send the evidence.

Frequently asked questions

Can I share a sample externally once redacted?

Yes, once names and IDs are removed and no kept field points back to a person, in line with Recital 26.

Will the control IDs survive?

Yes. Allow-list the control IDs and timestamps so the trail stays while identifiers go.

Is the evidence uploaded?

No. The app is fully offline, so it stays on your machine.